Legal information
Privacy Policy
This policy explains how Noventra Technologies SIA processes personal data on the website, in communication and when organising software projects.
Updated: 21 August 2026
1. Controller
The controller is Noventra Technologies SIA, registration number 40203772601. Privacy contact: noventratechnologies@inbox.eu, +371 26 772 612.
2. Data categories
- name, organisation and contact details;
- project type, budget, timing and enquiry content;
- correspondence, proposals, contracts, invoices and payment status;
- project contacts, roles and access information;
- test data or materials voluntarily provided by a client;
- technical data processed in hosting security logs, such as IP address, time, browser type and requested page.
3. Purposes and lawful bases
- enquiries and proposals — pre-contract steps and legitimate interests in communication;
- project delivery — contract, access, delivery, support and billing;
- legal obligations — accounting, tax and lawful authority requests;
- security and claims — legitimate interests in protecting systems and legal interests;
- marketing — only with an appropriate lawful basis and consent where required.
4. Required information and test data
Only data needed to prepare a response or contract is mandatory. Without it, we may be unable to offer or deliver a project. A client must not provide live sensitive or production data for testing without a written basis, secure channel and agreed processing arrangements.
5. Recipients and processors
Authorised personnel may access data, as may website hosting, email, IT, accounting, payment, legal or specialist project providers where necessary. Information may be disclosed to authorities where required by law. Personal data is not sold.
6. Transfers outside the EEA
Some technology providers may process data outside the European Economic Area. Where that occurs, an applicable mechanism such as an adequacy decision or Standard Contractual Clauses is used.
7. Retention
An enquiry that does not become a contract is generally retained for up to 24 months unless another period is justified. Contracts, invoices and accounting information are kept for applicable legal periods. Project materials and access are deleted, returned or anonymised according to the contract and technically feasible backup cycles.
8. Security
Risk-appropriate technical and organisational measures are used, including access controls, separate work environments and provider review. No internet transmission is entirely risk-free, so do not submit passwords, identity documents or unnecessary sensitive data in the general enquiry form.
9. Your rights
Where applicable, you may request access, correction, erasure, restriction and portability, and object to processing based on legitimate interests. Consent may be withdrawn for future processing. Identity may be verified before a request is completed.
10. Complaints and updates
Please contact us first with questions. You also have the right to complain to the Latvian Data State Inspectorate: dvi.gov.lv. This policy may be updated when processes or legal requirements change.